Tartışma

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Başlatan The Hacker News · 20 Tem 2026 17:44 · 1 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.

A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi